ComboFix 09-11-08.03 - Ayyub Maadani 09/11/2009 10:35.2.2 - NTFSx86
Running from: c:\documents and settings\Ayyub Maadani\Desktop\ComboFix.exe
Command switches used :: c:\documents and settings\Ayyub Maadani\Desktop\CFscript.txt
AV: McAfee VirusScan *On-access scanning disabled* (Updated) {84B5EE75-6421-4CDE-A33A-DD43BA9FAD83}
FW: McAfee Personal Firewall *enabled* {94894B63-8C7F-4050-BDA4-813CA00DA3E8}
* Created a new restore point
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
--------------- FCopy ---------------
c:\windows\$NtServicePackUninstall$\eventlog.dll --> c:\windows\system32\eventlog.dll
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_TDSSSERV
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226ED}
-------\Legacy_{79007602-0CDB-4405-9DBF-1257BB3226EE}
((((((((((((((((((((((((( Files Created from 2009-10-09 to 2009-11-09 )))))))))))))))))))))))))))))))
.
2009-11-09 10:35 . 2004-08-03 23:56 55808 ----a-w- c:\windows\system32\eventlog.dll
2009-11-09 10:35 . 2004-08-03 23:56 55808 ----a-w- c:\windows\system32\dllcache\eventlog.dll
2009-11-01 17:12 . 2009-11-01 17:12 -------- dc----w- C:\Sun
2009-11-01 16:46 . 2009-11-01 17:40 -------- d-----w- c:\documents and settings\Ayyub Maadani\.SunDownloadManager
2009-10-30 11:15 . 2009-10-30 11:13 102664 ----a-w- c:\windows\system32\drivers\tmcomm.sys
2009-10-30 11:13 . 2009-10-30 11:16 -------- d-----w- c:\documents and settings\Ayyub Maadani\.housecall6.6
2009-10-17 18:26 . 2009-10-17 18:26 -------- d-----w- c:\documents and settings\Ibrahim Maadani\Application Data\Trusteer
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-11-09 11:17 . 2008-01-26 22:04 -------- d-----w- c:\documents and settings\All Users\Application Data\Kontiki
2009-11-09 11:04 . 2007-11-07 18:30 -------- d-----w- c:\program files\lg_fwupdate
2009-11-09 10:57 . 2004-09-30 19:49 288 ----a-w- c:\windows\system32\DVCStateBkp-{00000004-00000000-00000000-00001102-00000004-10031102}.dat
2009-11-09 10:57 . 2004-09-30 19:49 288 ----a-w- c:\windows\system32\DVCState-{00000004-00000000-00000000-00001102-00000004-10031102}.dat
2009-11-09 10:04 . 2007-01-13 11:52 -------- d-----w- c:\program files\McAfee
2009-11-05 21:32 . 2008-09-19 18:26 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2009-11-01 19:42 . 2004-11-07 08:33 -------- d-----w- c:\program files\Common Files\Adobe
2009-11-01 17:53 . 2004-09-30 19:36 -------- d-----w- c:\program files\Java
2009-10-17 18:55 . 2004-10-14 19:29 86352 ----a-w- c:\documents and settings\Ibrahim Maadani\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-29 19:03 . 2009-09-29 16:03 -------- d-----w- c:\program files\HandBrake
2009-09-29 16:12 . 2009-09-29 16:12 -------- d-----w- c:\documents and settings\Ayyub Maadani\Application Data\HandBrake
2009-09-29 15:45 . 2009-07-06 18:49 -------- d-----w- c:\documents and settings\Ayyub Maadani\Application Data\Red Kawa
2009-09-29 09:58 . 2009-09-29 09:58 -------- d-----w- c:\program files\Regensoft
2009-09-16 09:22 . 2007-01-13 11:53 40552 ----a-w- c:\windows\system32\drivers\mfesmfk.sys
2009-09-16 09:22 . 2007-01-13 11:53 35272 ----a-w- c:\windows\system32\drivers\mfebopk.sys
2009-09-16 09:22 . 2007-01-13 11:53 79816 ----a-w- c:\windows\system32\drivers\mfeavfk.sys
2009-09-16 09:22 . 2007-01-13 11:53 214664 ----a-w- c:\windows\system32\drivers\mfehidk.sys
2009-09-16 09:22 . 2007-01-13 11:53 34248 ----a-w- c:\windows\system32\drivers\mferkdk.sys
2009-09-15 08:54 . 2004-11-05 09:51 86352 ----a-w- c:\documents and settings\Sandra Maadani\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
2009-09-15 08:53 . 2009-09-15 08:53 -------- d-----w- c:\documents and settings\Sandra Maadani\Application Data\Trusteer
2009-09-15 08:19 . 2009-09-15 08:19 -------- d-----w- c:\documents and settings\NetworkService\Application Data\McAfee
2009-09-14 19:33 . 2007-01-13 11:46 -------- d-----w- c:\documents and settings\All Users\Application Data\McAfee
2009-09-14 12:05 . 2008-07-22 11:39 -------- d-----w- c:\documents and settings\Ayyub Maadani\Application Data\Skype
2009-09-14 11:52 . 2006-12-25 11:40 -------- d-----w- c:\program files\Windows Media Connect 2
2009-09-14 10:06 . 2008-07-22 11:42 -------- d-----w- c:\documents and settings\Ayyub Maadani\Application Data\skypePM
2009-09-10 14:54 . 2008-09-19 18:26 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-09-10 14:53 . 2008-09-19 18:26 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-09-01 20:21 . 2009-09-01 20:20 1925024 ----a-w- c:\documents and settings\All Users\Application Data\NOS\Adobe_Downloads\install_flash_player.exe
2009-08-18 21:40 . 2004-10-18 19:35 86352 ----a-w- c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\GDIPFONTCACHEV1.DAT
.
(((((((((((((((((((((((((((((
SnapShot@2009-11-06_16.33.30 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-11-09 10:58 . 2009-11-09 10:58 16384 c:\windows\Temp\Perflib_Perfdata_5f4.dat
+ 2009-11-09 10:58 . 2009-11-09 10:58 16384 c:\windows\Temp\Perflib_Perfdata_5e4.dat
+ 2002-09-03 01:08 . 2009-11-09 10:08 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
- 2002-09-03 01:08 . 2009-11-06 15:42 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Local Settings\History\History.IE5\INDEX.DAT
+ 2009-11-06 19:57 . 2009-11-09 10:08 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\index.dat
- 2002-09-03 01:08 . 2009-11-06 15:42 32768 c:\windows\SYSTEM32\CONFIG\systemprofile\Cookies\INDEX.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SB Audigy 2 Startup Menu"="/L:ENG" [X]
"kdx"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"Google Update"="c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\Google\Update\GoogleUpdate.exe" [2009-09-14 133104]
"ares destiny"="c:\program files\Ares Destiny\Ares.exe" [2007-08-07 2970112]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files\Java\jre6\bin\jusched.exe" [2008-12-26 136600]
"IAAnotif"="c:\program files\Intel\Intel Application Accelerator\iaanotif.exe" [2004-06-29 135168]
"PCMService"="c:\program files\Dell\Media Experience\PCMService.exe" [2004-04-11 290816]
"IntelMeM"="c:\program files\Intel\Modem Event Monitor\IntelMEM.exe" [2003-09-03 221184]
"CTSysVol"="c:\program files\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe" [2002-10-29 49152]
"CTDVDDet"="c:\program files\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE" [2002-09-30 45056]
"UpdReg"="c:\windows\UpdReg.EXE" [2000-05-11 90112]
"Dell Photo AIO Printer 922"="c:\program files\Dell Photo AIO Printer 922\dlbtbmgr.exe" [2004-03-29 290816]
"LGODDFU"="c:\program files\lg_fwupdate\fwupdate.exe" [2007-11-07 249856]
"mcagent_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2009-09-17 645328]
"McENUI"="c:\progra~1\McAfee\MHN\McENUI.exe" [2009-07-07 1176808]
"4oD"="c:\program files\Kontiki\KHost.exe" [2007-11-27 1032376]
"QuickTime Task"="c:\program files\QuickTime\qttask.exe" [2009-01-05 413696]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2009-10-03 35696]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2009-09-04 935288]
"Malwarebytes Anti-Malware (reboot)"="c:\program files\Malwarebytes' Anti-Malware\mbam.exe" [2009-09-10 1312080]
"CTHelper"="CTHELPER.EXE" - c:\windows\SYSTEM32\CTHELPER.EXE [2003-02-20 28672]
"AsioReg"="CTASIO.DLL" - c:\windows\SYSTEM32\CTASIO.DLL [2003-02-20 110592]
"BluetoothAuthenticationAgent"="bthprops.cpl" - c:\windows\SYSTEM32\bthprops.cpl [2008-04-14 110592]
c:\documents and settings\Ayyub Maadani\Start Menu\Programs\Startup\
SDK Tray Menu.lnk - c:\sun\SDK\jdk\bin\javaw.exe [2009-11-1 139264]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Microsoft Office.lnk - c:\program files\Microsoft Office\Office10\OSA.EXE [2001-2-13 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\LMIinit]
2007-05-25 14:22 63040 ----a-w- c:\windows\SYSTEM32\LMIinit.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Adobe Reader Speed Launch.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Adobe Reader Speed Launch.lnk
backup=c:\windows\pss\Adobe Reader Speed Launch.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Bluetooth.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk
backup=c:\windows\pss\Bluetooth.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package Menu.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package Menu.lnk
backup=c:\windows\pss\Picture Package Menu.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Picture Package VCD Maker.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Picture Package VCD Maker.lnk
backup=c:\windows\pss\Picture Package VCD Maker.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Nintendo Wi-Fi USB Connector Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Nintendo Wi-Fi USB Connector Registration Tool.lnk
backup=c:\windows\pss\Run Nintendo Wi-Fi USB Connector Registration Tool.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^All Users^Start Menu^Programs^Startup^Run Registration Tool.lnk]
path=c:\documents and settings\All Users\Start Menu\Programs\Startup\Run Registration Tool.lnk
backup=c:\windows\pss\Run Registration Tool.lnkCommon Startup
[HKLM\~\startupfolder\C:^Documents and Settings^Ayyub Maadani^Start Menu^Programs^Startup^BBC iPlayer Desktop.lnk]
path=c:\documents and settings\Ayyub Maadani\Start Menu\Programs\Startup\BBC iPlayer Desktop.lnk
backup=c:\windows\pss\BBC iPlayer Desktop.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Ayyub Maadani^Start Menu^Programs^Startup^DiscinDisK.lnk]
path=c:\documents and settings\Ayyub Maadani\Start Menu\Programs\Startup\DiscinDisK.lnk
backup=c:\windows\pss\DiscinDisK.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Ayyub Maadani^Start Menu^Programs^Startup^Wallpaper Changer.lnk]
path=c:\documents and settings\Ayyub Maadani\Start Menu\Programs\Startup\Wallpaper Changer.lnk
backup=c:\windows\pss\Wallpaper Changer.lnkStartup
[HKLM\~\startupfolder\C:^Documents and Settings^Ayyub Maadani^Start Menu^Programs^Startup^wpc.lnk]
path=c:\documents and settings\Ayyub Maadani\Start Menu\Programs\Startup\wpc.lnk
backup=c:\windows\pss\wpc.lnkStartup
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Messenger\\msmsgs.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YPager.exe"=
"c:\\Program Files\\Yahoo!\\Messenger\\YServer.exe"=
"c:\\Program Files\\EA GAMES\\The Battle for Middle-earth (tm)\\game.dat"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"c:\\Program Files\\uTorrent\\uTorrent.exe"=
"c:\\Program Files\\Kontiki\\KService.exe"=
"c:\\Program Files\\McAfee\\MBK\\McAfeeDataBackup.exe"=
"c:\\Program Files\\Ares Destiny\\Ares.exe"=
"c:\\Program Files\\Common Files\\AOL\\Loader\\aolload.exe"=
"c:\\Program Files\\AIM6\\aim6.exe"=
"c:\\Program Files\\NetMeeting\\conf.exe"=
"c:\\WINDOWS\\SYSTEM32\\rtcshare.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"%windir%\\system32\\drivers\\svchost.exe"=
"c:\\Program Files\\Veoh Networks\\VeohWebPlayer\\veohwebplayer.exe"=
"c:\\WINDOWS\\SYSTEM32\\PnkBstrA.exe"=
"c:\\WINDOWS\\SYSTEM32\\PnkBstrB.exe"=
"c:\\Program Files\\WiFiConnector\\NintendoWFCReg.exe"=
"c:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"c:\\Program Files\\Skype\\Phone\\Skype.exe"=
R2 0134541257761057mcinstcleanup;McAfee Application Installer Cleanup (0134541257761057);c:\windows\TEMP\013454~1.EXE [x]
R3 EMSLink;EMS Inter-Link driver V3.0;c:\windows\system32\Drivers\EM3Link.sys [2006-12-02 9744]
R4 LMIRfsClientNP;LMIRfsClientNP; [x]
S1 RapportKELL;RapportKELL;c:\program files\Trusteer\Rapport\bin\RapportKELL.sys [2009-08-18 58728]
S1 RapportPG;RapportPG;c:\program files\Trusteer\Rapport\bin\RapportPG.sys [2009-08-18 333928]
S2 LMIInfo;LogMeIn Kernel Information Provider;c:\program files\LogMeIn\x86\RaInfo.sys [2007-04-17 12992]
S2 LMIRfsDriver;LogMeIn Remote File System Driver;c:\windows\system32\drivers\LMIRfsDriver.sys [2007-04-05 46112]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\McAfee\SiteAdvisor\McSACore.exe [2009-09-16 92296]
S2 NinjaVideo Helper.exe;NinjaVideo Helper;c:\program files\NinjaVideo\NinjaVideo Helper\NinjaVideo Helper.exe [2008-04-10 110592]
S2 RapportMgmtService;Rapport Management Service;c:\program files\Trusteer\Rapport\bin\RapportMgmtService.exe [2009-08-18 955624]
S2 Viewpoint Manager Service;Viewpoint Manager Service;c:\program files\Viewpoint\Common\ViewpointService.exe [2007-01-04 24652]
S3 CDCCG;Machoman V-CD 0.53!machoman China;c:\windows\system32\Drivers\cdg.sys [2002-01-08 26640]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - 0134541257761057MCINSTCLEANUP
*Deregistered* - mbr
.
Contents of the 'Scheduled Tasks' folder
2009-10-26 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2008-07-30 12:34]
2009-11-02 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3333968868-2200709785-3983559585-1008Core.job
- c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-14 10:22]
2009-11-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3333968868-2200709785-3983559585-1008UA.job
- c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\Google\Update\GoogleUpdate.exe [2009-09-14 10:22]
2004-10-14 c:\windows\Tasks\ISP signup reminder 1.job
- c:\windows\System32\OOBE\OOBEBALN.EXE [2002-08-29 00:12]
2008-07-15 c:\windows\Tasks\McDefragTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-13 11:22]
2009-09-01 c:\windows\Tasks\McQcTask.job
- c:\program files\mcafee\mqc\QcConsol.exe [2007-01-13 11:22]
.
.
------- Supplementary Scan -------
.
uStart Page =
uSearchMigratedDefaultURL =
hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8mSearch Bar =
hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.htmluInternet Connection Wizard,ShellNext = iexplore
uInternet Settings,ProxyOverride =
;*.local
uSearchURL,(Default) = hxxp://www.google.com/keyword/%s
IE: &Google Search - c:\program files\Google\GoogleToolbar1.dll/cmsearch.html
IE: &Translate English Word - c:\program files\Google\GoogleToolbar1.dll/cmwordtrans.html
IE: &Yahoo! Search - file:///c:\program files\Yahoo!\Common/ycsrch.htm
IE: Backward Links - c:\program files\Google\GoogleToolbar1.dll/cmbacklinks.html
IE: Cached Snapshot of Page - c:\program files\Google\GoogleToolbar1.dll/cmcache.html
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office10\EXCEL.EXE/3000
IE: Search with Wanadoo - c:\progra~1\Wanadoo\WSBar\WSBar.dll/VSearch.htm
IE: Similar Pages - c:\program files\Google\GoogleToolbar1.dll/cmsimilar.html
IE: Translate Page into English - c:\program files\Google\GoogleToolbar1.dll/cmtrans.html
IE: Yahoo! &Dictionary - file:///c:\program files\Yahoo!\Common/ycdict.htm
IE: Yahoo! &Maps - file:///c:\program files\Yahoo!\Common/ycmap.htm
FF - ProfilePath - c:\documents and settings\Ayyub Maadani\Application Data\Mozilla\Firefox\Profiles\q4beip64.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.co.uk/ig?hl=en&btnG=Google+Search
FF - prefs.js: keyword.URL - hxxp://search.freecause.com/search?fr=freecause&ourmark=3&type=59099&p=
FF - component: c:\documents and settings\Ayyub Maadani\Application Data\Mozilla\Firefox\Profiles\q4beip64.default\extensions\{19627815-20a6-46e6-be34-a0b6967c022a}\components\Engine.dll
FF - component: c:\program files\McAfee\SiteAdvisor\components\McFFPlg.dll
FF - plugin: c:\documents and settings\Ayyub Maadani\Application Data\Mozilla\Firefox\Profiles\q4beip64.default\extensions\battlefieldheroespatcher@ea.com\platform\WINNT_x86-msvc\plugins\npBFHUpdater.dll
FF - plugin: c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\Google\Update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\np-mswmp.dll
FF - plugin: c:\program files\Mozilla Firefox\plugins\NPMGWRAP.DLL
FF - plugin: c:\program files\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\NPVeohTVPlugin.dll
FF - plugin: c:\program files\Veoh Networks\VeohWebPlayer\npWebPlayerVideoPluginATL.dll
FF - plugin: c:\program files\Viewpoint\Viewpoint Experience Technology\npViewpoint.dll
FF - hȋdden: Microsoft .NET Framework Assistant: {20a82645-c095-46ed-80e3-08825760534b} - c:\windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
---- FIREFOX POLICIES ----
FF - user.js: dom.disable_open_during_load - true // Popupblocker control handled by McAfee Privacy Service
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-11-09 11:04
Windows 5.1.2600 Service Pack 3 NTFS
scanning hȋdden processes ...
scanning hȋdden autostart entries ...
scanning hȋdden files ...
scan completed successfully
hȋdden files: 0
**************************************************************************
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
device: opened successfully
user: MBR read successfully
called modules: ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys spbm.sys hal.dll >>UNKNOWN [0x87386938]<<
kernel: MBR read successfully
user & kernel MBR OK
Stealth MBR rootkit/Mebroot/Sinowal detector 0.3.7 by Gmer, http://www.gmer.net
iaStor.sys @ 0x0 0x0 bytes
\Driver\iaStor [ IRP_MJ_CREATE ] 0xF094 != 0xF74A9240 iaStor.sys
\Driver\iaStor [ IRP_MJ_CLOSE ] 0xF094 != 0xF74A9240 iaStor.sys
\Driver\iaStor [ IRP_MJ_DEVICE_CONTROL ] 0x127E8 != 0xF74A9240 iaStor.sys
\Driver\iaStor [ IRP_MJ_INTERNAL_DEVICE_CONTROL ] 0x12AA8 != 0xF74A9240 iaStor.sys
\Driver\iaStor [ IRP_MJ_POWER ] 0x17118 != 0xF74A9240 iaStor.sys
\Driver\iaStor [ IRP_MJ_SYSTEM_CONTROL ] 0x171A4 != 0xF74A9240 iaStor.sys
\Driver\iaStor IRP hooks detected !
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'winlogon.exe'(888)
c:\windows\system32\LMIinit.dll
c:\windows\system32\LMIRfsClientNP.dll
- - - - - - - > 'explorer.exe'(5052)
c:\windows\system32\WININET.dll
c:\progra~1\mcafee\SITEAD~1\saHook.dll
c:\program files\Trusteer\Rapport\bin\rooksbas.dll
c:\progra~1\WINDOW~2\wmpband.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\WPDShServiceObj.dll
c:\windows\system32\btncopy.dll
c:\program files\ArcSoft\PhotoImpression 5\share\pihook.dll
c:\windows\system32\PortableDeviceTypes.dll
c:\windows\system32\PortableDeviceApi.dll
c:\windows\system32\LMIRfsClientNP.dll
.
------------------------ Other Running Processes ------------------------
.
c:\windows\System32\Ati2evxx.exe
c:\program files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Bluetooth\Bluetooth Software\bin\btwdins.exe
c:\windows\System32\CTsvcCDA.exe
c:\program files\Intel\Intel Application Accelerator\iaantmon.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\program files\Kontiki\KService.exe
c:\progra~1\McAfee\MSC\mcmscsvc.exe
c:\program files\common files\mcafee\mna\mcnasvc.exe
c:\progra~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
c:\progra~1\McAfee\VIRUSS~1\mcshield.exe
c:\program files\McAfee\MSK\MskSrver.exe
c:\windows\system32\PnkBstrA.exe
c:\program files\CyberLink\Shared Files\RichVideo.exe
c:\windows\System32\MsPMSPSv.exe
c:\program files\Windows Media Player\WMPNetwk.exe
c:\program files\McAfee\MPF\MPFSrv.exe
c:\windows\system32\rundll32.exe
c:\progra~1\mcafee.com\agent\mcagent.exe
c:\windows\system32\rundll32.exe
c:\program files\Dell Photo AIO Printer 922\dlbtbmon.exe
c:\documents and settings\Ayyub Maadani\Local Settings\Application Data\Google\Update\1.2.183.13\GoogleCrashHandler.exe
.
**************************************************************************
.
Completion time: 2009-11-09 11:22 - machine was rebooted
ComboFix-quarantined-files.txt 2009-11-09 11:22
ComboFix2.txt 2009-11-06 16:52
Pre-Run: 122,053,271,552 bytes free
Post-Run: 122,030,059,520 bytes free
- - End Of File - - 330A92F90E02732F3822F3C17F8B6120